ASD's Blueprint for Secure Cloud

ASD Office Hardening - Macros Enabled for Trusted Publishers

This section describes the configuration of device configuration profiles within Microsoft Intune associated with systems built according to the guidance provided by ASD's Blueprint for Secure Cloud.

Estimated reading time: 5 minutes

Basics

ItemValue
NameASD Office Hardening - Macros Enabled for Trusted Publishers
Description
PlatformWindows 10 and later

Assignments

Included groups

ItemValue
GroupsAll devices

Excluded groups

None

Scope tags

ItemValue
Scope tagsDefault

Configuration settings

Administrative Templates

ItemValue
Windows Components > Microsoft Management Console
Restrict users to the explicitly permitted list of snap-ins (User)Enabled

Microsoft Access 2016

ItemValue
Disable Items in User Interface > Custom
Enter a command bar ID to disable (User)19092
Disable commands (User)Enabled
Application Settings > Security > Trust CenterDisable all except digitally signed macros
Block macros from running in Office files from the Internet (User)Enabled
Turn off trusted documents (User)Enabled
Turn off Trusted Documents on the network (User)Enabled
VBA Macro Notification Settings (User)Enabled
Application Settings > Security > Trust Center > Trusted Locations
Allow Trusted Locations on the network (User)Disabled
Disable all trusted locations (User)Enabled

Microsoft Excel 2016

ItemValue
Excel Options > Security > Trust CenterDisable all except digitally signed macros
Block macros from running in Office files from the Internet (User)Enabled
Trust access to Visual Basic Project (User)Disabled
Turn off trusted documents (User)Enabled
Turn off Trusted Documents on the network (User)Enabled
VBA Macro Notification Settings (User)Enabled
Excel Options > Security > Trust Center > Trusted Locations
Allow Trusted Locations on the network (User)Disabled
Disable all trusted locations (User)Enabled
Scan encrypted macros in Excel Open XML workbooks (User)Enabled
Scan encrypted macros (disabled)
Disable Items in User Interface > Custom
Enter a command bar ID to disable (User)19092
Disable commands (User)Enabled

Microsoft Office 2016

ItemValue
Security Settings > Trust Center
Allow mix of policy and user locations (User)Disabled
Macro Runtime Scan Scope (User)Enabled
Enable for all documents
Disable VBA for Office applications (User)Disabled
Disable all Trust Bar notifications for security issues (User)Enabled
Automation Security (User)Enabled
- Set the Automation Security level (User)Use application macro security level

Microsoft PowerPoint 2016

ItemValue
PowerPoint Options > Security > Trust CenterDisable all except digitally signed macros
Block macros from running in Office files from the Internet (User)Enabled
Trust access to Visual Basic Project (User)Disabled
Turn off trusted documents (User)Enabled
Turn off Trusted Documents on the network (User)Enabled
VBA Macro Notification Settings (User)Enabled
PowerPoint Options > Security > Trust Center > Trusted Locations
Allow Trusted Locations on the network (User)Disabled
Disable all trusted locations (User)Enabled
Scan encrypted macros in PowerPoint Open XML presentations (User)Enabled
Scan encrypted macros (default)
Disable Items in User Interface > Custom
Enter a command bar ID to disable (User)19092
Disable commands (User)Enabled

Microsoft Project 2016

ItemValue
Project Options > Security > Trust CenterDisable all except digitally signed macros
Allow Trusted Locations on the network (User)Disabled
Disable all trusted locations (User)Enabled
VBA Macro Notification Settings (User)Enabled

Microsoft Publisher 2016

ItemValue
Security > Trust CenterDisable all except digitally signed macros
VBA Macro Notification Settings (User)Enabled
Publisher Automation Security Level (User)Enabled
By UI (prompted)
Disable Items in User Interface > Custom
Enter a command bar ID to disable (User)19092
Disable commands (User)Enabled

Microsoft Visio 2016

ItemValue
Visio Options > Security > Trust CenterDisable all except digitally signed macros
Allow Trusted Locations on the network (User)Disabled
Block macros from running in Office files from the Internet (User)Enabled
Disable all trusted locations (User)Enabled
Turn off trusted documents (User)Enabled
Turn off Trusted Documents on the network (User)Enabled
VBA Macro Notification Settings (User)Enabled
Visio Options > Security > Macro Security
Enable Microsoft Visual Basic for Applications project creation (User)Disabled
Load Microsoft Visual Basic for Applications projects from text (User)Disabled
Disable Items in User Interface > Custom
Enter a command bar ID to disable (User)19092
Disable commands (User)Enabled

Microsoft Word 2016

ItemValue
Word Options > Security > Trust CenterDisable all except digitally signed macros
Block macros from running in Office files from the Internet (User)Enabled
Scan encrypted macros in Word Open XML documents (User)Enabled
Scan encrypted macros (default)
Trust access to Visual Basic Project (User)Disabled
Turn off trusted documents (User)Enabled
Turn off Trusted Documents on the network (User)Enabled
VBA Macro Notification Settings (User)Enabled
Word Options > Security > Trust Center > Trusted Locations
Allow Trusted Locations on the network (User)Disabled
Disable all trusted locations (User)Enabled
Disable Items in User Interface > Custom
Enter a command bar ID to disable (User)19092
Disable commands (User)Enabled

Security & Governance

Design

  • None identified

Configuration

References

  • None identified

Do you have a suggestion on how the above page could be improved? Get in touch! ASD's Blueprint for Secure Cloud is an open source project, and we would love to get your input. Submit an issue on our GitHub, or send us an email at blueprint@asd.gov.au

Acknowledgement of Country icon

Acknowledgement of Country
We acknowledge the Traditional Owners and Custodians of Country throughout Australia and their continuing connections to land, sea and communities. We pay our respects to them, their cultures and their Elders; past, present and emerging. We also recognise Australia's First Peoples' enduring contribution to Australia's national security.

Authorised by the Australian Government, Canberra